Registration Data and Privacy

July 16, 2026 ยท View on GitHub

Registration data identifies the person or organization responsible for a domain. Required fields and public visibility depend on the namespace, registry policy, and privacy controls.

Keep Data Accurate

Use the registration account's contact-data area to review:

  • Registrant name or organization
  • Email address
  • Phone number
  • Postal address
  • Billing address when applicable

Do not enter fictional data to avoid visibility. Inaccurate data can break recovery, notices, renewal, or policy compliance.

Understand Lookup Systems

Registration data may be available through WHOIS, RDAP, or a namespace-specific lookup system. Some fields may be redacted while operational data such as nameservers, registration dates, or status remains public.

The current registration interface and namespace policies determine which controls are available.

Privacy Practices

  • Use an organization-controlled contact address for organizational domains.
  • Use a monitored role email address when policy permits.
  • Keep recovery access separate from a single employee's device.
  • Do not publish Dashboard screenshots containing full contact data.
  • Review privacy settings after account updates.
  • Assume DNS record values are public.

Change Management

After updating registration data:

  1. Confirm the Dashboard shows the intended value.
  2. Verify that important notices reach the new email address.
  3. Review public registration data where applicable.
  4. Record the change date and responsible owner.

Staff or Organization Changes

Before a responsible person leaves:

  • Move the domain to an organization-controlled account if supported and appropriate.
  • Update contact and recovery addresses.
  • Rotate passwords and API keys.
  • Revoke old sessions and device access.
  • Transfer internal documentation and renewal ownership.

Continue to Account and API Security.